The Wired Connection faster Tour Prototype

Security · AWS + Claude

Supplier Risk Review

A first pass at every supplier's security posture, done for you. It gathers what each supplier has on file, flags what is missing, and sorts everyone by risk, so each review starts at step two. Security still makes the call.

Prototype. Supplier names, BAA status and contract dates are live from the Contract Renewals pipeline. Security posture (SOC 2, ISO 27001, HITRUST, certifications, findings) is compiled from each supplier's public trust center and security pages, with sources cited in each review, not from our internal documents. A production run reads the actual documents in each supplier folder. Anything not verifiable in public is marked Unknown rather than guessed.

How it all connects

Where the data comes from and how it flows into this view. Hover to trace a path; click any box to see what it does.

supplier docs BAA + contract dates SOC 2 / ISO / HITRUST reads + summarizes findings + tiers Google DriveSupplier governance docs Contract RenewalsBAA status + contract dates Public trust centersSOC 2 / ISO / HITRUST AnthropicReads and summarizes Supplier Risk first passInventory, gaps, control coverageAWS S3 + LambdaYOU ARE HERE Supplier Risk viewthis pageTiers · findings · checklist
data in this view

Why a gap is a bad thing

When a supplier is missing a key document, like a signed BAA or a current SOC 2, we are trusting them with our data on their word alone. If they have a breach, we may share the blame, the reporting duty and the cost. The worst gaps show up in red.

Why this is a good thing

Instead of an analyst spending hours reading paperwork before the real review can start, the reading is already done. Everyone is sorted by how much risk they carry, so the team spends its time on the suppliers that actually need it. The strong ones show up in green.

Suppliers reviewed
24
first pass complete
High / critical
7
need attention first
PHI suppliers, no BAA
11
top priority
Hold SOC 2
18 / 24
public evidence
Click a row for the full review. Click a supplier name for its contract one-pager.
Supplier Risk tier ? SOC 2 ? ISO 27001 ? HITRUST ? BAA ? Control coverage ? Handles PHI ? Source conf. ? Review
Thoropass Critical Unknown Unknown Unknown Missing
45%
Yes Low Review →
HealthVerity High Unknown Unknown Unknown Missing
60%
Yes Medium Review →
Welltality High Unknown Unknown Unknown In review
20%
Yes Medium Review →
Veradigm High Type II Unknown Unknown Missing
60%
Yes Medium Review →
MD Revolution High Unknown Unknown Unknown In review
30%
Yes Medium Review →
Highmark High Unknown Unknown HITRUST Compliant
35%
Yes Low Review →
Optum Insight High Unknown ISO 27001 Unknown In review
65%
Yes Medium Review →
Optimize Health Medium Type II Unknown Unknown Missing
75%
Yes Medium Review →
BambooHR Medium Type II ISO 27001 Unknown Missing
75%
Yes Medium Review →
NetSuite Medium Type II ISO 27001 Unknown Missing
80%
Yes High Review →
HubSpot Medium Type II No Unknown Missing
85%
Yes High Review →
UiPath Medium Type II ISO 27001 HITRUST Missing
85%
Yes Medium Review →
Oracle Medium Type II ISO 27001 Unknown Missing
88%
Yes Medium Review →
Box Medium Type II ISO 27001 Unknown Missing
88%
Yes High Review →
DocuSign Medium Type II ISO 27001 Unknown Missing
90%
Yes High Review →
Definitive Healthcare Medium Type I Unknown Unknown Missing
45%
No Medium Review →
Accuhealth Low unknown Unknown Unknown Compliant
35%
Yes Medium Review →
Smart Meter Low Type II Unknown Unknown Compliant
70%
Yes High Review →
Tenovi Low Type II Unknown Unknown Compliant
70%
Yes High Review →
Waystar Low Type II Unknown HITRUST Compliant
85%
Yes High Review →
Domo Low Type II ISO 27001 HITRUST Compliant
85%
Yes High Review →
Five9 Low Type II ISO 27001 Unknown Compliant
85%
Yes High Review →
Monday.com Low Type II ISO 27001 Unknown Compliant
88%
Yes High Review →
Twilio Low Type II ISO 27001 Unknown Compliant
90%
Yes High Review →